Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack

Critical infrastructure services provider Ventia over the weekend announced that it has taken some of its systems offline to contain a cyberattack.

Ventia provides long-term management, maintenance, and operations services for critical infrastructure organizations and for private entities across the defense, electricity and gas, environmental services, and water industries.

The company says it operates more than 400 sites in Australia and New Zealand, with a combined employee base of over 35,000.

In an incident notice on Saturday, the company announced that it decided to take some key systems offline in response to the incident, and that it had engaged with external experts and law enforcement to investigate it.

“As we work to restore our networks, we will prioritize the security and safety of our people, our customers, and our stakeholders,” the company said.

Ventia did not share details on the impact the incident has had, but said in an updated statement on Sunday that its operations are continuing while it monitors its network for any abnormal activity.

According to Ventia, all operations are expected to return to normal within the following days.

Advertisement. Scroll to continue reading.

Although the company did not share specifics on the incident, it is possible that file-encrypting ransomware was involved in the attack, as typical incident response measures in the event of ransomware involve taking systems offline to prevent it from spreading.

The company has yet to reveal whether any type of information was stolen during the attack.

SecurityWeek has emailed Ventia for additional details on the incident and will update this article as soon as a reply arrives.

Related: Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Related: Microsoft Says Early June Disruptions to Outlook, Cloud Platform, Were Cyberattacks

Related: Swiss Fear Government Data Stolen in Cyberattack

https://www.securityweek.com/critical-infrastructure-services-firm-ventia-takes-systems-offline-due-to-cyberattack/




After Zero-Day Attacks, MOVEit Turns to Security Service Packs

Faced with a barrage of ransomware attacks hitting zero-days in its MOVEit product line, Progress Software late Thursday announced plans to release regular service sacks promising a “predictable, simple and transparent process for product and security fixes.”

Less than a month after the notorious Cl0p ransomware gang started naming organizations hit by MOVEit zero-day exploits, Progress Software rolled out its first service pack with patches for at least three critical security defects that expose customer database content to malicious attackers.

“We have heard from you that a regular cadence and predictable timeline will enable you to better plan your resources and make it easier to adopt new product updates and fixes. As a part of these Service Packs, we will also be optimizing the installation process to make the upgrade process simpler,” Progress said in a note posted with the first service pack.

Software vendors typically use a service pack to deliver a collection of updates, fixes, features or enhancements to an application.  Service packs are delivered in the form of a single installable package.

Progress Software said the service packs would apply to its MOVEit products, including MOVEit Transfer and MOVEit Automation.

The initial service pack provides cover for CVE-2023-36934, a critical-severity bug in the Progress MOVEit Transfer tool.  The company described it as a SQL injection vulnerability that allows an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. 

“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” the company said of the most serious bug.

The service pack also includes patches for CVE-2023-36932, which covers multiple high-severity Progress MOVEit Transfer  vulnerabilities that allows authenticated attackers to gain unauthorized access to the MOVEit Transfer database. “An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” Progress said.

Advertisement. Scroll to continue reading.

Progress Software also included a fix for CVE-2023-36933, a high-severity bug that allows an attacker to invoke a method which results in an unhandled exception.  “Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.”

Related: MOVEit Users Urged to Patch Third Critical Vulnerability

Related: Ransomware Group Naming Victims of MOVEit Zero-Days

Related: New MOVEit Flaws Found as Attack Victims Come Forward

https://www.securityweek.com/after-zero-day-attacks-moveit-turns-to-security-service-packs/




Former Contractor Employee Charged for Hacking California Water Treatment Facility

A 53-year-old man from Tracy, California, has been charged for allegedly hacking into the systems of a water treatment facility in an attempt to delete critical software.

The suspect, Rambler Gallo, has been charged with “transmitting a program, information, code, and command to cause damage to a protected computer”, but this is a case of unauthorized access rather than actual hacking. 

Gallo worked for a company contracted by the town of Discovery Bay in California to operate its water treatment facility, which serves 15,000 residents. 

He worked at the company between 2016 and the end of 2020, and during this time he allegedly installed software that allowed him to access the facility’s systems from his personal computer. 

After he resigned in January 2021, he used that remote access software to enter the water facility’s systems and “transmitted a command to uninstall software that was the main hub of the facility’s computer network and that protected the entire water treatment system, including water pressure, filtration, and chemical levels,” according to a press release from authorities in the Northern District of California. 

Gallo faces up to 10 years in prison and a $250,000 fine. 

It’s not uncommon for water facilities to be targeted, including by former employees. One of the most well-known incidents involves the water plant in Oldsmar, Florida. While initially it was believed that malicious hackers had tried to poison the water supply, recent reports said the incident did not involve any hacking and it may have actually been the result of human error. 

Advertisement. Scroll to continue reading.

Related: US Says National Water Supply ‘Absolutely’ Vulnerable to Hackers

Related: Former Ubiquiti Employee Who Posed as Hacker Sentenced to Prison

Related: Former Cisco Employee Sentenced to Prison for Webex Hack

Related: Bipartisan Bill Proposes Cybersecurity Funds for Rural Water Systems

https://www.securityweek.com/former-contractor-employee-charged-for-hacking-california-water-treatment-facility/




Shell Confirms MOVEit-Related Breach After Ransomware Group Leaks Data

Energy giant Shell has confirmed that personal information belonging to employees has been compromised as a result of the recent MOVEit Transfer hack.

The Cl0p ransomware group exploited a zero-day vulnerability in the MOVEit managed file transfer (MFT) product to steal data from at least 130 organizations that had been using the solution. To date, at least 15 million individuals are believed to be impacted. 

The Russia-linked cybercrime gang has started naming victims that refused to negotiate on its leak website and Shell was among the first organizations.

In a brief statement issued on Wednesday, Shell finally confirmed being hit by the MOVEit hack, clarifying that the MFT software was “used by a small number of Shell employees and customers”. 

“Some personal information relating to employees of the BG Group has been accessed without authorisation,” the company said. 

It’s unclear exactly what type of information has been compromised, but impacted individuals are being notified. Toll-free phone numbers where additional information can be obtained have been made available for employees in Malaysia, South Africa, Singapore, Philippines, UK, Canada, Australia, Oman, Indonesia, Kazakhstan, and Netherlands, suggesting that affected people may be from these countries. 

Shell pointed out that “this was not a ransomware event” — likely referring to the fact that file-encrypting malware was not deployed in the attack — and that there is no evidence of any other IT systems being affected. 

Advertisement. Scroll to continue reading.

Shell confirmed the incident after the Cl0p cybercrime gang published files allegedly stolen from the firm. The group has made available 23 archive files labeled ‘part1’, which could suggest that they are in possession of more data. SecurityWeek was unable to download the archive files so it’s unclear what type of information they contain.

When they published the Shell files, the cybercriminals noted that the company did not want to negotiate.

It’s worth noting that Shell was also targeted by the Cl0p group in 2020, through a zero-day exploit targeting an Accellion file transfer service. The company confirmed at the time that the hackers had stolen personal and corporate data. 

Other major organizations that have been named by Cl0p and confirmed being affected by the recent MOVEit exploit include Siemens Energy, Schneider Electric, UCLA, and EY. 

Some government organizations have also admitted being hit, but the cybercriminals claim to have deleted all data obtained from these types of entities. 

Related: Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack

Related: MOVEit Customers Urged to Patch Third Critical Vulnerability

https://www.securityweek.com/shell-confirms-moveit-related-breach-after-ransomware-group-leaks-data/




Interpol: Key Member of Major Cybercrime Group Arrested in Africa

Interpol on Wednesday announced the arrest of a suspected senior member of the French-speaking cybercrime group known as Opera1er.

Also tracked as Common Raven, Desktop-Group, and NXSMS, the cyber gang is believed to have been involved in at least 30 successful attacks against African banks, financial services, mobile banking services, and telecoms firms.

Identified in 2018, Opera1er has been active since at least 2016 and, between 2019 and 2022, stole at least $11 million from victims in 15 countries across Africa, Latin America, and Asia. The total made by the group is believed to surpass the $30 million mark.

The group has been observed using spear-phishing emails to gain access to targeted organizations’ networks, deploying malware, and abusing compromised bank infrastructure, including the SWIFT messaging interface, to make fraudulent transactions to mule accounts.

Money mules would then withdraw the funds at ATMs, typically over weekends and public holidays.

Opera1er, Interpol notes, has also engaged in large-scale business email compromise (BEC) scams, which typically involve sending fraudulent invoices to employees in charge of making payments and tricking them into transferring funds to attacker-controlled bank accounts.

In early June, authorities in the African country of Côte d’Ivoire (Ivory Coast) arrested an individual believed to be connected to cyberattacks targeting financial institutions in Africa.

Advertisement. Scroll to continue reading.

The suspect is believed to be a senior member of Opera1er and his arrest is expected to significantly impact the group’s illicit activities, Interpol says.

The arrest was made as part of Operation Nervone, an international effort involving Interpol, law enforcement in Africa, Côte d’Ivoire’s Direction de l’Information et des Traces Technologiques (DITT), and private cybersecurity and telecommunications firms.

The US Secret Service’s Criminal Investigative Division also provided information, confirming leads.

Related: ‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns

Related: 120 Arrested as Cybercrime Website Genesis Market Seized by FBI

Related: Microsoft: BEC Scammers Use Residential IPs to Evade Detection

https://www.securityweek.com/interpol-alleged-member-of-major-cybercrime-group-arrested-in-africa/




Siemens Energy, Schneider Electric Targeted by Ransomware Group in MOVEit Attack

Energy giants Schneider Electric and Siemens Energy have confirmed being targeted by a ransomware group in the recent campaign exploiting a vulnerability in Progress Software’s MOVEit managed file transfer (MFT) software.

The Cl0p ransomware group claims to have exploited a MOVEit zero-day vulnerability to access the files of hundreds of organizations that had been using the MFT product. Several major companies have confirmed being hit and the cybercriminals have started naming victims that refuse to pay up. 

This week, the hackers added over a dozen more alleged victims to their leak website. Germany-based Siemens Energy, a spinoff of Siemens’ energy business, and France-based automation and energy management giant Schneider Electric are among the companies named this week on the Cl0p site.

Siemens Energy has confirmed for SecurityWeek that it’s among the targets of the MOVEit attack and said it took immediate action in response to the incident.

“Based on the current analysis no critical data has been compromised and our operations have not been affected,” the company said in an emailed statement. 

Schneider Electric told SecurityWeek that the company became aware of the MOVEit software zero-day on May 30 and promptly deployed mitigations to secure data and infrastructure. 

“Subsequently, on June 26th, 2023, Schneider Electric was made aware of a claim mentioning that we have been the victim of a cyber-attack relative to MOVEit vulnerabilities. Our cybersecurity team is currently investigating this claim as well,” the company said.

Advertisement. Scroll to continue reading.

Other major organizations listed recently by Cl0p on its leak website include Sony, EY, PwC, Cognizant, AbbVie and UCLA, but it’s unclear if all of them have been targeted in the MOVEit attack. SecurityWeek has reached out to each of them for comment. 

The attackers have started leaking data allegedly stolen from energy giant Shell, which has confirmed being targeted in the MOVEit attack. SecurityWeek has reached out to Shell as well. 

Some evidence suggests that the cybercriminals have known about the MOVEit zero-day vulnerability since 2021, but mass attacks only started in late May 2023. 

While some government organizations have also confirmed being impacted, the hackers claim they have deleted all the data obtained from such entities, noting that they are financially motivated and “do not care about politics”. They allegedly deleted data obtained from more than 30 government and government-related organizations. 

The cybercriminals also claim on their website that they are the only group to have exploited the zero-day before it was patched and they are the only ones in possession of the data obtained as a result of the attack. 

Related: Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack

Related: MOVEit Customers Urged to Patch Third Critical Vulnerability

Related: New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward

https://www.securityweek.com/siemens-energy-schneider-electric-targeted-by-ransomware-group-in-moveit-attack/




3-Year Probe Into Encrypted Phones Led to Seizure of Hundreds of Tons of Drugs, Prosecutors Say

Investigations triggered by the cracking of encrypted phones three years ago have so far led to more than 6,500 arrests worldwide and the seizure of hundreds of tons of drugs, French, Dutch and European Union prosecutors said Tuesday.

The announcement underscored the staggering scale of criminality — mainly drugs and arms smuggling and money laundering — that was uncovered as a result of police and prosecutors effectively listening in to criminals using encrypted EncroChat phones.

“It helped to prevent violent attacks, attempted murders, corruption and large-scale drug transports, as well as obtain large-scale information on organised crime,” European Union police and judicial cooperation agencies Europol and Eurojust said in a statement.

The French and Dutch investigation gained access to more than 115 million encrypted communications between some 60,000 criminals via servers in the northern French town of Roubaix, prosecutors said at a news conference in the nearby city of Lille.

As a result, 6,558 suspects have been arrested worldwide, including 197 “high-value targets.” Seized drugs included 30.5 million pills, 103.5 metric tons (114 tons) of cocaine, 163.4 metric tons (180 tons) of cannabis and 3.3 metric tons (3.6 tons) of heroin. The investigations also led to nearly 740 million euros ($809 million) in cash being recovered and assets or bank accounts worth another 154 million euros ($168 million) frozen.

Police announced in 2020 they had cracked the encryption of EncroChat phones and effectively listened in on criminal gangs.

EncroChat sold phones for around 1,000 euros ($1,094) worldwide and offered subscriptions with global coverage for 1,500 euros ($1,641) per six months. The devices were marketed as offering complete anonymity and were said to be untraceable and easy to erase if a user was arrested.

Advertisement. Scroll to continue reading.

French law enforcement authorities launched investigations into the company operating EncroChat in 2017. The probe led to a device being installed that was able to evade the phones’ encryption and gain access to users’ communications.

Authorities also have identified and detained some of the alleged leaders of the EncroChat provider, Carole Etienne, chief prosecutor at the judicial tribunal of Lille, told reporters.

“Three people were arrested on June 22 in Spain and handed over to France on the basis of European arrest warrants,” she said. “Other individuals have been located outside the European Union and have not yet been charged.”EncroChat is not the only secret communications network used by criminals that have been infiltrated by law enforcement authorities.In March 2021, Belgian police arrested dozens of people and seized more than 17 metric tons (18.7 tons) of cocaine after cracking another encrypted chat system, called Sky ECC.

The FBI and other law enforcement agencies went a step further and created an encrypted service — ANOM — that was marketed to criminals in a global sting that led to the arrest of more than 800 suspects and seizure of more than 32 metric tons (35.2 tons) of drugs, including cocaine, cannabis, amphetamines and methamphetamines.

Related: ‘What’s the Price Today?’: FBI Phone App Reaped Secrets of Global Drug Networks

Related: ‘Grim’ Criminal Abuse of ChatGPT is Coming, Europol Warns

https://www.securityweek.com/3-year-probe-into-encrypted-phones-led-to-seizure-of-hundreds-of-tons-of-drugs-prosecutors-say/




Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Some services at Petro-Canada gas stations have been disrupted following a cyberattack on parent company Suncor, one of the largest energy companies in North America. 

Suncor is a Canada-based company that produces oil and runs several refineries in North America. The organization owns a network of more than 1,800 Petro-Canada retail and wholesale locations. 

In a brief statement issued on June 25, Suncor said it had experienced a cybersecurity incident that may impact some transactions with suppliers and customers. The company said it brought in third-party experts to aid investigation and response efforts, and noted that authorities have been notified.

“At this time, we are not aware of any evidence that customer, supplier or employee data has been compromised or misused as a result of this situation,” the company said.

On June 26, Petro-Canada said on Twitter that it’s working with Suncor to respond to the cybersecurity incident, informing customers that some services may be unavailable, including credit card payments and car washes. 

Petro-Canada also informed customers that they will not be able to log into their loyalty program account from the app or website.  

It’s unclear if the disruptions have been caused by a ransomware attack. In these types of attacks, cybercriminals can encrypt files and steal data from the victim’s systems — they can conduct only one or both types of activities. 

Advertisement. Scroll to continue reading.

In 2021, American oil pipeline system Colonial Pipeline was targeted in a ransomware attack that resulted both in significant disruption and the theft of information, with the company paying millions of dollars to the attackers. 

SecurityWeek has sent an email to Suncor asking if the incident involved ransomware and whether the company received a ransom demand from the attackers. This article will be updated if the energy giant responds.

Threat actors have been observed selling access to energy organizations, including oil and gas firms, on cybercrime forums. 

Related: US Offshore Oil and Gas Infrastructure at Significant Risk of Cyberattacks

Related: ABB Oil and Gas Flow Computer Hack Can Prevent Utilities From Billing Customers

Related: European Oil Port Terminals Hit by Cyberattack

https://www.securityweek.com/gas-stations-impacted-by-cyberattack-on-canadian-energy-giant-suncor/




British Twitter Hacker Sentenced to Prison in US

A British national has been sentenced to five years in prison in the US for his role in hacking schemes targeting cryptocurrency wallets, Twitter accounts, and other social media accounts.

The man, Joseph James O’Connor, also known as ‘PlugwalkJoe’, 24, was arrested in Spain in July 2021 and extradited to the US in April this year. He pleaded guilty in court in May.

According to court documents, between March 2019 and May 2019, O’Connor and others engaged in a SIM swapping attack resulting in the theft of $794,000 worth of cryptocurrency from a Manhattan-based cryptocurrency company.

As part of the attack, the perpetrators took over the phone numbers of three executives at the victim company to gain access to accounts and computers and steal cryptocurrency from wallets maintained on behalf of two clients.

O’Connor and his co-conspirators attempted to launder the stolen funds through dozens of transactions. Some of the crypto-coins were deposited in wallets controlled by O’Connor.

In July 2020, O’Connor participated in a scheme targeting multiple Twitter accounts, after gaining unauthorized access to internal tools used by the social media platform.

Using these administrative tools, the perpetrators took over multiple high-profile accounts, such as those of Jeff Bezos, Joe Biden, Mike Bloomberg, Bill Gates, and Elon Musk. The attackers targeted roughly 130 accounts.

Advertisement. Scroll to continue reading.

According to court documents, O’Connor used SIM swapping to access without authorization two accounts on TikTok and Snapchat, threatening to release sensitive, personal materials about both victims.

In June and July 2020, O’Connor stalked and threatened a minor, orchestrating a series of swatting attacks on the victim. He made swatting calls and sent swatting messages to the police, a high school, a restaurant, and a sheriff’s department in the victim’s area.

O’Connor pled guilty to conspiracy to commit computer intrusions, wire fraud, and money laundering, computer intrusion, extortion, stalking, and making threats.

He was also sentenced to three years of supervised release and ordered to pay $794,000 in forfeiture.

Related: Romanian Operator of Bulletproof Hosting Service Sentenced to Prison in US

Related: Former Ubiquiti Employee Who Posed as Hacker Sentenced to Prison

Related: Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced

https://www.securityweek.com/british-twitter-hacker-sentenced-to-prison-in-us/




In Other News: Microsoft Win32 App Isolation,Tsunami Hits Linux Servers, ChatGPT Credentials Exposed on Dark Web

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:

Oracle EU Sovereign Cloud

Oracle has launched a new EU Sovereign Cloud offering designed to help organizations across the European Union gain more control over data privacy and sovereignty requirements. Oracle EU Sovereign Cloud is located and operated entirely within the European Union and aligned with EU standards of practice.

NineID seed funding

Advertisement. Scroll to continue reading.

Belgian access management start-up NineID raised $2.6 million in seed funding to build a secure bridge between the digital and physical worlds of corporate security.  After raising $1.4 million in 2022 and launching its product, the company announced raising another $1.2 million, closing its $2.6 million seed round. 

Microsoft launches public preview of Win32 app isolation

Microsoft has launched a public preview of Win32 app isolation, created to “encapsulate and restrict” the execution of processes. Built on the foundation of AppContainers, Win32 app isolation is a new security feature designed to be the default isolation standard on Windows clients and will bring added security features to help defend against attacks that leverage vulnerabilities in applications.

Zyxel patches critical vulnerability in NAS devices

Zyxel released patches for a critical-severity pre-authentication command injection vulnerability (CVE-2023-27992) impacting some NAS models, warning that unauthenticated attackers could exploit the bug via HTTP requests to execute operating system (OS) commands remotely.

Tsunami botnet hits Linux SSH servers

AhnLab Security Emergency Response Center (ASEC) discovered an attack campaign that consists of the Tsunami DDoS bot being installed on “inadequately managed” Linux SSH servers. According to AhnLab, hackers managed to install the Tsunami bot malware, along with various other malware such as ShellBot, XMRig CoinMiner, and Log Cleaner.

DDoS botnets target IoT vulnerabilities

Palo Alto Networks warned of a new malware campaign exploiting dozens of vulnerabilities in routers, CCTV cameras, and other IoT devices to gain control over them and infect them with a variant of the Mirai botnet, capable of launching DDoS attacks.

Fortinet has observed attacks targeting a recent vulnerability in TP-Link Archer AX21 (AX1800) routers (CVE-2023-1389) to infect them with the Condi DDoS bot.

U.S. Tracked Huawei, ZTE Workers at Suspected Chinese Spy Sites in Cuba

U.S. officials reportedly tracked workers from Chinese telecom companies Huawei Technologies and ZTE entering and exiting suspected Chinese spy facilities in Cuba, the WSJ reports.

UPS users targeted in Smishing attacks 

UPS is notifying individuals in Canada of an ongoing SMS phishing (Smishing) campaign designed to steal their personal information, including names and addresses. 

“We are constantly vigilant when it comes to phishing and other attempts from bad actors. UPS is aware of reports relating to an SMS phishing (“Smishing”) scheme focused on certain shippers and some of their customers in Canada. UPS has been working with partners in the delivery chain to understand how that fraud was being perpetrated, as well as with law enforcement and third-party experts to identify the cause of this scheme and to put a stop to it,” UPS told SecurityWeek.

Mondelez employees exposed in law firm hack 

Personal information of more than 51,000 current and former workers at snack food giant Mondelez International was exposed in a data breach at law firm Bryan Cave Leighton Paisner LLC, Mondelez said. The breach occurred in February 2023 and was discovered on May 22, 2023.

Over 100,000 ChatGPT credentials on the dark web

Singapore-based cybersecurity firm Group-IB has discovered over 100,000 ChatGPT credentials in the logs of information stealers traded on the dark web. Between June 2022 and May 2023, Asia-Pacific had the largest number of stolen ChatGPT accounts.

GitHub repositories vulnerable to RepoJacking

Aqua Security says that millions of GitHub repositories might be vulnerable to RepoJacking, potentially exposing organizations to remote code execution attacks. RepoJacking occurs when a user or organization changes their name, resulting in GitHub creating new repository links and automatically redirecting projects to the new repository. However, the old username/organization name becomes available and the attacker can register it and create a malicious repository that breaks the redirection.

https://www.securityweek.com/in-other-news-microsoft-win32-app-isolationtsunami-hits-linux-servers-chatgpt-credentials-exposed-on-dark-web/